
Explanation:
Box 1: No
No - To enable MUA for Vault1, a resource guard must be deployed to Sub1.
The Backup vault is in Sub1.
You create a Resource Guard in a different tenant than the Backup Fault, to get maximum protection.
Note: The Security admin creates the Resource Guard. We recommend that you create it in a different subscription or a different tenant as the vault.
However, it should be in the same region as the vault.
Box 2: Yes
Yes - A user in Group2 must approve changes-made by a user in Group1 to the backup policies of Vault1.
Group1 has administrators who manage Backup for Sub1.
Group2 has administrators who manage security for Sub1 and Sub2.
Box 3: No
No - A user in Group1 that activates Assignment1 can disable soft for the backups of Vault1, without the approval of a user in Group2.
You can't disable the protected operations - Disable soft delete and Remove MUA protection.
Reference:
https://learn.microsoft.com/en-us/azure/backup/multi-user-authorization